CVE-2026-72062

UnknownEPSS 0.21%

Last modified

CVE-2026-72062 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: gpio: mt7621: avoid corruption of shared interrupt trigger state The bank-shared fields like 'rising' and 'falling' are modified using non-atomic read-modify-write operations. Since every gpio chip instance represents an entire bank of 32 pins, if 'mediatek_gpio_irq_type()' is called concurrently for different IRQs on the same bank a possible overwrite of each other's configuration is possible. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: gpio: mt7621: avoid corruption of shared interrupt trigger state The bank-shared fields like 'rising' and 'falling' are modified using non-atomic read-modify-write operations. Since every gpio chip instance represents an entire bank of 32 pins, if 'mediatek_gpio_irq_type()' is called concurrently for different IRQs on the same bank a possible overwrite of each other's configuration is possible. Thus, protect this state with 'gpio_generic_lock_irqsave' lock in the same way it is handled in irp_chip 'mediatek_gpio_irq_mask()' and 'mediatek_gpio_irq_unmask()' callbacks.

Metrics

EPSS Probability
0.21%

11.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 4ba9c3afda41213ec98c30053e32963892e6dc7c, < bddf9314a57a243dd11ed945ba11e146e331257e; >= 4ba9c3afda41213ec98c30053e32963892e6dc7c, < 207d3ebf36f654a43a934addeb4d6775cb2dd667; >= 4ba9c3afda41213ec98c30053e32963892e6dc7c, < 877a243006788aaa586b2d087f27c9f3628071b0; >= 4ba9c3afda41213ec98c30053e32963892e6dc7c, < d3b9026ef78da3018a7d2c5a9c9d611de6d45c47; >= 4ba9c3afda41213ec98c30053e32963892e6dc7c, < a60a40c9ba30edd06d3fb4215fdf430ed968728e; >= 4ba9c3afda41213ec98c30053e32963892e6dc7c, < 1781172526d1092323af443fa03f00e6de560401
LinuxLinux4.19

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-72062?
In the Linux kernel, the following vulnerability has been resolved: gpio: mt7621: avoid corruption of shared interrupt trigger state The bank-shared fields like 'rising' and 'falling' are modified using non-atomic read-modify-write operations. Since every gpio chip instance represents an entire bank of 32 pins, if 'mediatek_gpio_irq_type()' is called concurrently for different IRQs on the same bank a possible overwrite of each other's configuration is possible. Thus, protect this state with 'gpio_generic_lock_irqsave' lock in the same way it is handled in irp_chip 'mediatek_gpio_irq_mask()' and 'mediatek_gpio_irq_unmask()' callbacks.
How severe is CVE-2026-72062?
Severity scoring for CVE-2026-72062 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-72062?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-72062?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST